CVE-2013-2451: Low severity ORACLE JRE vulnerability
It was discovered that the Networking component did not properly enforce exclusive port binding. A local attacker could exploit this flaw to bind to ports intended to be exclusively bound.
Other sources
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier, and OpenJDK 7, allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Networking. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to improper enforcement of exclusive port binds when running on Windows, which allows attackers to bind to ports that are already in use.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2451?
CVE-2013-2451 is classified with a medium severity level due to the potential for a local attacker to bind to ports intended for exclusive access, which may lead to further exploits.
How do I fix CVE-2013-2451?
To mitigate CVE-2013-2451, users should upgrade to the latest version of Oracle Java SE and apply security patches provided by Oracle.
Who is affected by CVE-2013-2451?
CVE-2013-2451 affects users of Oracle Java SE 7 Update 21 and earlier versions, including specific updates of JDK and JRE.
What type of vulnerability is CVE-2013-2451?
CVE-2013-2451 is a local privilege escalation vulnerability due to improper enforcement of exclusive port binding.
Can CVE-2013-2451 be exploited remotely?
No, CVE-2013-2451 can only be exploited by local attackers who have access to the affected system.